PT-2026-60195 · Directus · Directus
CVE-2026-61836
·
Published
2026-07-15
·
Updated
2026-07-28
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Directus versions prior to 12.0.0
Description
When response caching is enabled, the cache-key derivation process in the
get-cache-key.ts file omits critical authorization context, including share, role, roles, admin, app, and policies. Because share tokens and anonymous requests may both be identified as user null, different shares or anonymous clients requesting the same URL and query may receive a cached response filtered for a different user's permissions without a new permission evaluation.Recommendations
Update to version 12.0.0.
Exploit
Fix
DoS
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Directus